CVE-2025-64711 is a self-XSS vulnerability affecting PrivateBin versions 1.7.7 through 2.0.2, where dragging a file with HTML in its filename can execute arbitrary JavaScript in the victim's browser session. This medium-severity vulnerability (CVSS 5.4) requires user interaction (UI:R) and specific conditions, such as file upload enabled and the victim being a macOS or Linux user. While it can lead to exfiltration of sensitive data like plaintext or encryption keys, its practical impact is considered low due to the need for local file system access or social engineering to create/download a malicious file, and the non-persistent, local-session nature of the exploit. There is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.7.7, < 2.0.3CPE matchmatch criteria | cpe:2.3:a:privatebin:privatebin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.